Aruba Networks ClearPass数据库凭证泄露和SQL注入漏洞
发表日期:2014-07-07 15:56:00
Aruba Networks ClearPass数据库凭证泄露和SQL注入漏洞
CVE-ID:CVE-2014-4013,CVE-2014-4031
受影响系统:
Aruba Networks Networks ClearPass 6.3.x
Aruba Networks Networks ClearPass 6.2.x
Aruba Networks Networks ClearPass 6.1.x
Aruba Networks Networks ClearPass 6.0.x
详细信息:
Aruba Networks ClearPass是Wi-Fi网络和有线网络访问接入方案。
Aruba Networks ClearPass 6.0.x, 6.1.x, 6.2.x, 6.3.x版本没有正确过滤ClearPass Policy Manager组件内的输入,这可使恶意用户注入任意SQL代码,篡改SQL查询,泄露ClearPass Policy Manager数据库凭证。
来源:
Nate Roberts
参考信息:
http://secunia.com/advisories/58936/
解决办法:
厂商补丁:
Aruba Networks
--------------
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:
http://www.arubanetworks.com/products/clearpass/guest/
http://www.arubanetworks.com/support/alerts/aid-07032014.txt